MCP server
Connect an MCP-compatible AI assistant to your CRM, with permissions you approve.
What it is
The CRM runs a remote MCP server. MCP, the Model Context Protocol, is the standard way AI assistants connect to outside tools. Connect an MCP-compatible assistant, such as Claude Code, and it can look things up in your CRM and — if you allow it — create and update records, always within your own permissions.
If you want an assistant inside the CRM itself, that is SWARECO AI. MCP is for assistants that live somewhere else. Both use the same permission-checked tools.
Connecting
The server address is:
https://crm.swareco.com/mcp
- Add the server to your assistant using that address. In Claude Code, for example:
claude mcp add --transport http swareco https://crm.swareco.com/mcp - Your assistant opens a consent page in your browser. Sign in to the CRM if asked.
- Read the permissions on the page, untick any you do not want to give, and approve.
- Go back to your assistant. It now holds a token for the permissions you approved.
Tokens are short-lived. Your assistant renews them in the background, and you do not sign in again each time.
Permissions you approve
A new connection gets read-only access unless you grant more. The consent page lists every permission your role allows, with the ones the assistant asked for already ticked. Anything that can change data sits in a separate warning panel, and granting any of it needs an extra confirmation tick.
| Permission | What it allows | Who can grant it |
|---|---|---|
| Contacts | Read contacts; create new ones and change existing ones | Read: everyone. Write: admins and above |
| Opportunities | Read deals and the pipeline; create new ones and change existing ones | Read: everyone. Write: admins and above |
| Offerings | Read your products and services; create and change them | Admins and above |
| Appointments | Read the appointments you can see; book, change and cancel them | Everyone |
| Comments | Read comments on contacts and deals; add new ones | Everyone |
| Files | List the files on a contact or deal; upload new ones | Everyone |
| Analytics | Read account-wide KPI and pipeline analytics | Admins and above. No tool uses it yet |
If an assistant later needs a permission it does not hold, it can ask again and you see the consent page for the combined set. Connections made earlier keep exactly what they were granted.
What a connected assistant can do
| Records | Tools |
|---|---|
| Contacts | contacts_list, contacts_get, contacts_create, contacts_update, contacts_count |
| Deals | opportunities_list, opportunities_get, opportunities_create, opportunities_update |
| Offerings | offerings_list, offerings_get, offerings_create, offerings_update |
| Appointments | appointments_list, appointments_get, appointments_create, appointments_update, appointments_cancel |
| Comments | comments_list, comments_create |
| Files | documents_list, documents_prepare_upload, documents_create |
| Connection | whoami — which account the connection belongs to |
- A deal's additional contacts and offerings can be read and set, and contacts and deals can be assigned to a teammate by email address.
- Cancelling an appointment sets its status to cancelled. The record and its history stay.
- Comments are plain text. An
@in a comment from an assistant does not notify anyone. - Creating or cancelling an appointment sends the usual notifications, as a Calendly booking does.
Uploading a file
File contents are too large to travel inside a tool call, so an upload takes three steps: the assistant asks for a short-lived upload link, sends the file's bytes to that link itself, then attaches the uploaded file to the record. That needs an assistant that can make an HTTP request — Claude Code can; a chat-only assistant cannot.
The attached file goes through the same checks as any upload: content-type allowlist, 25 MB cap and virus scan. Tools return file names and details, never a file's contents. The server never fetches a web address on an assistant's behalf.
What it can never do
- Delete. There is no delete permission and no delete tool, so no instruction can reach one.
- Reach another account. Every lookup runs through your account. An identifier from elsewhere is answered exactly like one that does not exist.
- Change more than one record per call. There is no bulk tool.
- Go beyond your role. Each call is checked as you, at the moment it is made. If you are demoted, the connection loses that access straight away.
Your role and field permissions apply
- Fields your role cannot see are left out of what an assistant reads.
- A write that includes a field your role cannot change is refused as a whole, naming the field.
- Members read and book only the appointments assigned to them.
- Contact, deal and offering writes need an admin or above, even though a member can change some of them in the app.
Records and history
Changes made through MCP appear in history as Your Name (MCP), so they are never mistaken for something you typed yourself.
Limits and cautions
- Rate limits. Write requests are limited per person and per client. A client that hits the limit is told to wait and try again.
- Create is not safe to retry. If an assistant repeats a create after a timeout, you can end up with two records. Updates set fields to the values given, so repeating them changes nothing further.
- Treat record text as untrusted. A connected assistant reads whatever is in your records, including text visitors typed into a public form. Connect only assistants you trust, grant write access only when you need it, and check history if something looks off.
For developers
The server uses OAuth 2.1 with PKCE (S256) and publishes its discovery documents at the standard well-known
paths. Clients can register with a Client ID Metadata Document, an HTTPS address that describes the client; native
clients can use a loopback redirect on any port. It speaks MCP revisions 2026-07-28 and
2025-11-25 over Streamable HTTP, with JSON responses.
Something inaccurate or missing? Tell us — we would rather fix the docs than have you guess.